My PC was hijacked by a notify dll hijacker.
I have tried every thing but could not remove it.
It results in openning a browser page every 2 minutes and directing to this url:
http://www.ad-w-a-r-e.com/cgi-bin/PopupV3?ID={1DB1B121-4506-5844-2BFE-7444F90EEE22}&type=normal&mSkip=1&rnd=7752 .
this url, when opened, opens another web page, which changes every time, and shows all stuff of commercial etc.
The Hijacker is slowing my machine tremedesly, even at start up. it also caused for the scanner to cease working and shut my debugging privilages off.
I have followed the advices here and from other places - with no luck.
the only Software to have discover this hijacker was ADAWARE AWAY, a screen capture of the scan out come is attached.
I have downloaded EWIDO - a log file is attached, and also HIJACK THIS- a log file attached.
Also attached is a screen capture of REGISTERY EDITOR, showing the keys embedded by this hijacker in the REGISTERY.
Here is the HIjACK THIS LOG FILE:
Logfile of HijackThis v1.99.1
Scan saved at 12:01:56, on 28/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\slserv.exe
D:\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
D:\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
D:\trendmicro anti spyware\Tmas.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Maxthon\Maxthon.exe
d:\ewido\security suite\ewidoguard.exe
d:\ewido\security suite\ewidoctrl.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.walla.co.il/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.il
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.walla.co.il/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] d:\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Spyware Vanisher] D:\spywarevanisher-free\FreeScanner.exe -FastScan
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = D:\trendmicro anti spyware\Tmas.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - d:\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - d:\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft....738&clcid=0x409
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop...cpConnCheck.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com...ideoControl.cab
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} (shizmoo Class) - http://playroom.icq....yssey_web11.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} (LauncherV1 Class) - http://www.tapuz.co....in/launcher.cab
O16 - DPF: {DD7C9B9F-6534-464B-AFF0-A3D9439A3A18} (TCM3Control Control) - http://video.esc.co.il/TCM3Control.cab
O16 - DPF: {F59AB0C4-3443-4551-A78F-C101F9DE0215} (LauncherV1 Class) - http://irc.tapuz.co....ew/launcher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8AA81ED9-7747-4AEF-86E8-C04EF327AE8D}: NameServer = 192.116.202.222 213.8.172.83
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\ir20l5fm1.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - d:\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - d:\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\TuneUp Utilities 2006\WinStylerThemeSvc.exe
Here is EWIDO SCAN RESULTS FILE:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:59:29, 28/10/2005
+ Report-Checksum: 4E7FA609
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx\\.Owner -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/mfc42.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/msvcrt.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/olepro32.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/vbiewer.ocx\\.Owner -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/vbiewer.ocx\\{0B682CC1-FB40-4006-A5DD-99EDD3C9095D} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6CB0-410C-8C3D-8FA8D2011D0A} -> Spyware.iMesh : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-C1EC-0345-6EC2-4D0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00320615-B6C2-40A6-8F99-F1C52D674FAD} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B682CC1-FB40-4006-A5DD-99EDD3C9095D} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30192F8D-0958-44E6-B54D-331FD39AC959} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{302A3240-4805-4A34-97D7-1645A0B08410} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B55BB05-0B4D-44FD-81A6-B136188F5DEB} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{89044184-F260-4FDD-8FAB-2662814846E5} -> Spyware.SpectorPro : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E1089BC-1AE8-4685-8D77-6721E5C318A8} -> Spyware.ComLoad : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1757981266-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B} -> Spyware.SaveNow : Cleaned with backup
[1624] C:\WINDOWS\system32\dhnhupnp.dll -> Spyware.Look2Me : Error during cleaning
[1976] C:\WINDOWS\system32\dhnhupnp.dll -> Spyware.Look2Me : Error during cleaning C:\WINDOWS\system32\ekpsrv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\potorsvc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\090-ntpass.xpn -> Not-A-Virus.Hacktool.Ntpass : Cleaned with backup
C:\WINDOWS\system32\lkghours.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dlocx.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dbserial.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\o2pq0c75ef.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dadmoprp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wuashext.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\maawt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\Cookies\yarden@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\yarden@pro-market[1].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\moshik@pro-market[2].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\moshik@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\WINDOWS\Temp\Cookies\moshik@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Moshik\Local Settings\Temp\Temporary Internet Files\Content.IE5\SDAFOD2F\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Moshik\Local Settings\Temp\Cookies\moshik@pro-market[2].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\Documents and Settings\Moshik\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Adition : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Hyperbanner : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\moshik@linkbuddies[1].txt -> Spyware.Cookie.Linkbuddies : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Moshik\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\Temporary Internet Files\Content.IE5\YJW1S7U5\istdownload[1].exe -> TrojanDownloader.IstBar.lw : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\Cookies\yarden@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\Cookies\yarden@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\ysb.dll -> TrojanDownloader.IstBar.lv : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\jfghjhhfgudk.exe -> TrojanDownloader.IstBar.lw : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temp\jfgudk.exe -> TrojanDownloader.IstBar.lw : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temporary Internet Files\Content.IE5\CHIJGHMJ\ysbinstall_1003585[1].exe -> TrojanDownloader.IstBar.is : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temporary Internet Files\Content.IE5\CHIJGHMJ\ysb[1].dll -> TrojanDownloader.IstBar.lv : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temporary Internet Files\Content.IE5\CHIJGHMJ\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temporary Internet Files\Content.IE5\T3WR5JGB\istdownload[1].exe -> TrojanDownloader.IstBar.lw : Cleaned with backup
C:\Documents and Settings\Yarden\Local Settings\Temporary Internet Files\Content.IE5\T3WR5JGB\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Adition : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Hyperbanner : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@mysearch[2].txt -> Spyware.Cookie.Mysearch : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Adocean : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@linkbuddies[1].txt -> Spyware.Cookie.Linkbuddies : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\yarden@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Yarden\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\temp.fr6DCE -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Carmel\Local Settings\Temp\THI591C.tmp\polall2c.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Carmel\Local Settings\Temp\THI434C.tmp\polall2c.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Carmel\Local Settings\Temp\THI64C3.tmp\polall2c.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Carmel\Local Settings\Temp\THI3EBC.tmp\polall2c.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Carmel\Cookies\carmel@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Carmel\Cookies\carmel@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Carmel\Cookies\carmel@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Carmel\Cookies\carmel@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Carmel\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Program Files\ACD Systems\fff-ap6x-reg.exe -> Trojan.Small.cr : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP136\A0046937.exe -> TrojanDownloader.IstBar.lu : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048210.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048762.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048780.EXE -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048781.EXE -> Spyware.SmartLoad : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048782.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048783.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048784.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048785.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048786.exe -> TrojanDownloader.IstBar.ij : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048796.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0048883.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049348.exe -> TrojanDownloader.IstBar.is : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049350.dll -> TrojanDownloader.IstBar.lv : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049552.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049556.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049559.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049560.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049562.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049563.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049565.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049570.exe -> Spyware.Zestyfind : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049571.exe -> Backdoor.Wootbot.z : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049573.exe -> Trojan.Pakes : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049576.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049691.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049692.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049693.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0049831.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050004.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050017.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050031.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050077.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050086.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050094.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP140\A0050102.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050113.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050114.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050120.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050125.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050169.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050173.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050176.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050261.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050280.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP141\A0050340.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP142\A0050396.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP142\A0050405.dll -> Spyware.Look2Me : Cleaned with backup
D:\new\Tiberian Sun\RAZOR.EXE -> TrojanDropper.Small.ux : Cleaned with backup
D:\System Volume Information\_restore{AED10DC8-86B3-4850-9547-D076E18CD962}\RP29\A0016011.EXE -> TrojanDropper.Small.ux : Cleaned with backup
D:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048778.exe -> TrojanDownloader.VB.qr : Cleaned with backup
D:\System Volume Information\_restore{3B188B9A-9659-41A8-9051-B0891515B8AB}\RP139\A0048779.exe -> TrojanDownloader.VB.qr : Cleaned with backup
E:\תוכנות שונות\acdseepowerpackv6.0.3.18crackfff.zip/fff-ap6x-reg.exe -> Trojan.Small.cr : Error during cleaning
::Report End
Please - I need your help.
Thanks in advance.
Moshik